Plan0101
Custom softwareEngineeringAI DiagnosisAI SystemsProducts & WorkCompany
Evaluate with AI
Legal · Data

Data Processing and DPA

This page describes general principles when PLAN0101 processes data on behalf of a customer. A signed customer-specific DPA may formalize additional obligations where required.

Last updated: September 2, 2026

DocumentsPrivacyTermsCookiesAcceptable UseData ProcessingSecurity

1. Roles

Where a customer determines the essential purposes and means of processing and PLAN0101 processes data only to provide the service, the customer will typically act as controller and PLAN0101 as processor, subject to applicable law and the agreement.

2. Instructions

We process customer data according to documented and reasonable instructions related to the service, unless applicable law requires otherwise.

3. Confidentiality and access

Access is limited to personnel or providers that need it to operate, support or protect the service and that are subject to appropriate confidentiality obligations.

4. Security measures

  • Encryption in transit through HTTPS/TLS for compatible public services.
  • Access controls and least privilege where applicable.
  • Secret management outside source code and reduced credential exposure.
  • Logging, monitoring and review of relevant events appropriate to the service.
  • Dependency maintenance and vulnerability remediation according to risk.

5. Subprocessors

We may use infrastructure, database, email, observability, AI and other providers necessary to deliver the service. We seek to evaluate providers and limit processing to the contracted purpose. A customer-specific subprocessor list may be agreed where required.

6. Security incidents

If we become aware of a confirmed security incident affecting customer data under our control and a notification obligation applies, we will seek to notify the customer without undue delay and provide reasonably available information for response.

7. Data subject requests

Where applicable and technically reasonable, we will assist customers with access, correction, deletion and other rights requests involving data processed on their behalf.

8. Return and deletion

At service termination, export, return, deletion or required retention will be handled according to the agreement, technical configuration and applicable legal obligations.

9. International transfers

Where processing involves regulated transfers, the parties may agree on contractual clauses or other mechanisms required by applicable law.

10. Contractual DPA

This page is informational and does not replace a signed DPA where one is required. PLAN0101 can incorporate a data processing addendum into customer documentation.

Legal and privacy contact

contacto@plan0101.com

Plan0101

Custom software, digital products and AI systems for real operations.

ServicesCustom softwareEngineeringAI SystemsEstimatorAI Diagnosis
ProductsCloserWinCloserWin case studyClyvelClyvel case studyProducts & WorkInsights
MarketsArgentinaMexicoSpainUnited KingdomUnited StatesBrazil
Company & legalAbout usSecurityPrivacyTermsCookiesData ProcessingAcceptable UseEvaluate your project with AI Contact
© 2026 PLAN0101.Custom software · CloserWin · Clyvel